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BR, BW, BY, BZ, CA, CH, CN, CO, CR, CU, CZ, DE, DK, 
DM, DZ, EC, EE, EG, ES, FI, GB, GD, GE, GH, GM, HR, 
HU, ID, IL, IN, IS, KE, KG, KM, KP, KR, KZ, LC, LK, 
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TZ, UA, UG, US, UZ, VC, VN, YU, ZA, ZM, ZW. 

(84) ft^H(asa>ftL^ifiy. ±xow.m<D&®umtf^ 

fig): ARIPO (BW, GH, GM, KE, LS, MW, MZ, NA, SD, 
SL, SZ, TZ, UG, ZM, ZW), 3.— z> v T (AM, AZ, BY, 
KG, KZ, MD, RU, TJ, TM), 3 — □ V /< (AT, BE, BG, 
CH, CY, CZ, DE, DK, EE, ES, FI, FR, GB, GR, HU, IE, 



== (54) Title: INFORMATION PROCESSING METHOD, DECODING METHOD, INFORMATION PROCESSING DEVICE, AND 
== COMPUTER PROGRAM 

= (54)*iB©««i: fi^ffia^a. fc^u'tif^aigm. tfixizur/tfi-* ■ -jwj^u 




u1 u2 u3 u4 u5 u6 u7 u8 u9 u10 u11 u12 u13 u14 u15 u16 



filu4 
NV19 £ 

salt19, salt9, salt4, salt2 



ID 

m 
m 

o 
o 

o 



AA.. NV19 AND SALT19, SALT9, SALT4, SALT2 
ARE SUPPLIED TO RECEIVER U4. 

(57) Abstract: There is provided an encrypted text providing structure based on the CS method capable of reducing the information 
amount to be stored in the device for decrypting the encrypted texl and the calculation amount. A Rabin Tree is generated as a one- 
direction tree where a node correspondence value is set for each of the nodes constituting a hierarchical tree. A node correspondence 
value NV a is set in such a manner that it can be calculated by applying a function f based on a node correspondence value NV b set to 
correspond to at least one lower node and a node addition variable salt b . A node key NK corresponding to each node is configured so 
that it can be calculated by inputting a node correspondence value RV corresponding to each node and applying a function He. With 
this configuration, it is possible to reduce the information amount required to be held safely in a receiver and reduce the calculation 
amount required for calculating the node key in the receiver, there by realizing effective encryption, distribution, and decryption. 
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[oooi] ^rnmfe, ffimmxm. m^m^m. ^^mmmmmm, ftrnz^v^ 

=c-l/W7^3^jj^\Z3io\ ^S&fcjfeh/fl ^Complete Subtree^ (CS^5£ 

[0002] ^#<£>*— -r^x-*, BM^O®^-*, ff—J&v??^ &m 

Content) £l«) #\ ^^—^MIO^h^—^^LT, fo<5V ^CD(Compacl 
Disc), DVD(Digital Versatile Disk), MD(Mini Disk)^Off&|Efifcj&# (^fT)* 
^LT^iiLTV^ 0 dtlb^MS^^r^ft, if (Dffi^-fZPC (Personal Co 
mputer)^7V~ &51 ^fS^-iM&g^ ^*3H##&3^fifcfcVv-cfl:££ 

[0003] -S^t*-*, SHt^-^, #<^^x>^[i, — Jl£itt^<7)ffr££-fc5v^j& 

[0004] 4fe aE^fcfcl ^Ttt, titm*&i??sl'mz%d.0ctZ^f^m*&fai&fa&&& 
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[0012] M2^irv-yi4\zm^^xbfitz^mmmm^JEfm^tLx^m( ) j^ 

x&*yhv-?%it-Lxh^^mmmmmmLxmJnirz> 0 
[ooi3] r©^, v#~?(mm£H&m^mmmm^/~v*-(m2xfexE\ix 

[0014] |g|2^i-^(jT1i, y— K2, 6, 15©y-K^~ Sr^T, ^T^^-Kc^Bf 
E(NK , Kc), E(NK , Kc), E(NK , Kc) 

2 6 15 

<D9g?s&%$i$ l Lx, *yb?-mmh^^mmmmzfe%hLxmmi-Z) 0 % 

*3, E(A, B) fix-^B^fiATBlf^kLfex-^^^-r^o SfcNKnte, 0^ 
^^>^-Kc^y-K^-NK TI^^UcB£-^7^E(NK , Kc)i\ 

2 2 

^7^;>^-Kc£/-K=3f— NK TBt^kL^Bf ^kx— ^E(NK , Kc)i, =t>^ 

6 6 
15 15 

[0015] _Ud3o(Dfl£ ^-A'^f^9, f^J^fflWI^iiiSl^ffl^T^^M^^tc^fg-rix 

^^5ff^*L«efite, ±fBC3o<7)Bf^^iiffl$^3ooy-K=3f— NK 
, NK , NK (D^-ftlhUftLX^ftWV, ^B^^^LT^ m^ffl^ 

6 15 



WO 2006/030635 



5 



PCT/JP2005/015814 



##fp:£itKl : Advances in Cryptography— Crypto 2001, Lecture Note 
s in Computer Science 2139, Springer, 2001 pp. 41 — 62TD. Naor, M 
. Naor and J. Lotspiech^tTRevocation and Tracing Schemes for Sta 
teless Receivers"] 

mm^xm2:2oo4m^tmm±^j^>^^^"fmM, pp. 189-194 

##fr»3:2004^Bt^Mf#ir^^y^>^^A^m^, pp. 195-199 

[0022] Jf%wn, z<D£o%ftmz!&&xft£tiitho-vb*). -fu-v^^Y^yw 

■>a> (Broadcast Encryption) ^^(DM^W^f^tL-Xjmhti^Complete Subt 
rcc^^(CS^^)^-^fB]^i:LTfS:^tt?)Rabin Tree£ffll^T3fc&U ££>f- 

[0023] £<b^ jl-fl^cfi, ^P^TIi, CS#5£Kl*tU RabinBf -^-^S^XRabin Tr 

ifc^usunr-tt, mzni,<nwirz>i>\ Rabmm o-^hm-t^t^, rs 

[0024] *3P^<£>^l<£>ffi!|®te, 
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M 

<fe><5> 

[oo28] *&m<Dffin&mj?8k<D--mn-mmfc3s\,^x, mm-^^^^y 

^X/lrlN'X | M | /2<D2o©±#ft§g$c£3£&, WmMmW-r^, 
**ry7°2 : Z (O^m^mtiir^y^^mW. : H££#)5, 

M 

1 1 

ez* ^Si-^fie^Lr^v^A^ii^i-^, 

M 

a. Tffi5t> 
[^20] 

te^p , = (NV L//2j - H (I \\ salt ,)) mod M 

i 

i 

2N— lfiCO | M | tfyh©ifc(y— WJSte) :NV , NV , ■ • •, NV £\ 

1 2 2N-1 

2N-2m<D&V~-} f ttto&&) :salt , salt , ■ • ■, salt SrW^U ^££2 

2 3 2N-1 

^*©#y-Kl(l=l~2N-l)07-K^jifi^j;^V-K#l)n«i1-^, 
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GR22] 



temp j = (NV I //2 I ® # ' (/)) mod Af 



i 

b. tmp 1/2 modM£j£#\ 40<D#©5^W"f :h/J&VS: % KK^/HtfV— K*f 
J&ffiNV^Mo 

2N-HS<£> | M | t^hOi((y-K^jil:) :NV , NV , • • •, NV 

1 2 2N-1 

2N-2B(DW(y-VH1]U^m :salt , salt , salt £rfct57JU r_tUb£2 

2 3 2N-1 

[0032] $t>iz. *mw<D%2<Dmmz. 

a 

b b 

l^Ji^igfflLTcSD (Subset Difference) ^^S^V^3xS1-?)f-7^yh 
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a. TfS^ 
[fc24] 



tewp , = {NV Ul2 |© # *"'(/)) mod M 



b. imp 1/2 modM£*#\ 4o<D^?<D5*>^>V^-f KK^/^tfV— R*f 
i 

"firry?*-. 

2N-HB<£> | M | bf^/h(D#:(y— K*tJSflS) :NV , NV , • • •, NV 

1 2 2N-1 

2N-2{|g]<»(/-KttMic) :salt , salt , • • salt £ffi/jU -tUb£2 

2 3 2N-1 

Ki 0= i~2N- 1) <D;—\?#fcMft£Xf/—\ f WJja&Wcb1rz, 

[0034] ^PJ(Dm30{RiJg«, 

mB^-Xfrb, § ao^i-^y-K^ffiNvty-K#Ao^icsaiti^s^5v^ 

Bf fi©l)iy-Kdr-^, g BO^i-5y-KmffiNV^/-K#*P^i[sal 
t«<5VNT^{±l«y-K^f— wm^y^ts 
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[$C26] 

Nv y/2]= (NV f 2 ® #**'(/)) mod M 

M I \Z.-?y\£l"f-fZ>WMr£m. H sa,tl (l)tt,l(^)^LT, §|$CH£salt Hk jg 

[0039] ^Pjl0^4^Uffi«, 

I^S *«^{3lS<3<Xn— Kdr^h^^yXv^ay^-efc^SD (Subset Diff 

^UU^I^^f-Xir^h^-T^V^^^, ftfire/-Kmffi:NV^/-K^^icsal 
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[oo4i] ^mm(D\m^mmm<D-mmmm\^^x, me-^*^^ 

o 

[0042] £^ ^^^tt^asigo-njs^niisv^, Mteff ms^s, $ 

[0043] ^PJI^ffMS^m^-^M^^^v^, ffiriE-;fcft*£fi!c¥© 

rt»b*Bffi$fc (breadth first order) T*tt^-Lfc/-K#-*§-l (^) 
— KK^c/V)^/— K^flSNV (1 = 2, 3, 2N-1)^\T^ V 
Bfc28] 



^ L//2J = (iVF 7 2 + //(/ || ,)) mod A/ 

M 

[0044] «0^Offi«»g(7)-^MS#}C^oV^T, tfffB-^^T^^t-^ 
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frbm^ft (breadth first order) 'TMtf-S-UL/— K#^l (^^) ©I^^fc^/ 

— K1(^/^)(D/— KjfctJCSffiNV(l = 2, 3, 2N-1)#\ T^* 

i 

Hfc30] 

^L//2J= (^ F / 2 0 '(/))mod M 



M | ^yt^-fZmmXh'Q, H saltl (l)fi,l(^)^x=tLT, HS^H^salt 0, jg 

i 

[0047] ^mm(D\m^mmm<D-mmmm^^x^ mm-^^^m 

^yy2:^~V/~V<Dy~Vft!fcmtLX<DmNV GZ* ^T^MzM^f^ 

1 M 

a. Tn'riStx 
[f(3l] 
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^M^S^fe (breadth first order) "e#-^L^/-K#-§'l(^/V) <75^j£$^#y— 

Kl(^yl,)<Dy— K*f^NV(l = 2, 3, 2N-l)^\K, 

i 

[«320 

^L//2j = (^/ 2 e # mod M 

M | \Z.^y\fly^-r^mWcQhK), H saW (l) H\ l(^) fcttLT, r«H£salt 0, ig 

i 

[0049] ^IM^ffilSMagi'S^-^W^iCfeV^, 

ft, 
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[0051] ^0J!(Dtf^M^ffO-^M1i^*3V^, tulBBt^jl^^tt, 

l®/l;fc<£|i:±&/— K£LT£>/1'— HSrl^U (breadth first order) "C# 

[0052] £«b^ ^PJ(OM-$8^ffl^g^-«^#^*3V^, MfB/-K^-^tH¥^ 
J3\ 2ftjzlZ3o\;^X±{tiy-Vfch^9c (breadth first order) Xtt-$-Ltc/-V 
m^U^M <Dmfe£thtc& J~m^)<D/~Vttf£MNV (1 = 2, 3, 2N- 



[it34] 



A^F L//2j = (NV 7 2 + // (/ || jflA ,)) mod M 



M 

[0053] *mw<Dtfm&mm\R<D-'MMmmz&^x, BuK/-K^-£um£ 

NK=Hc(NV) 

fo£U NK: A-K*-, NV: A-K*tJftfU Hc:^tV^H^ % 
[0054] £t>^ «PJ(DfffB^a^-^(D-^M#(-feV^, BuSS7-K^"-^|iS¥S 
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2#7M£&V^T±&y— K^^l^^fe (breadth first order) "Ctt-£Lfcy— K# 

-^l(^)(7)iS^^c#y-Kl(^/^)(Dy-K^fiSNV(l = 2 ) 3, 2N-1) 

i 

[ft36] 

NV li/ii = (^/ 2 © # *""(/)) mod M 

i 

•So 

[oo56] £^ ^mmm^i^m^ 

a 

b b 
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a 

b b 

^mm^m^mMimxnx.^m^xhv, RSA^zmm^tt^tim. 

[0061] «P^CO-»^(7)*^^J:tb«\ /-Rtt«ifc(salt)o^£^HL 

fcRabin Troc^M(l2^fflV^ri-T:\ g{f MiJ^:fe^T/-K^-£ltffi-f 5fc 

[oo62] [mi2#*witem*mmz^xnwirz>wxhz> 0 

[[23]Complcte Subtree (CS) ^lUd&l ^Til^-f^y— K^20^|l£1-5Pg 

mm*m&%mwirmxh% 0 

[MComplete Subtree (CS) ^{H&l ^T^— 7#/&<DgfM(0j$oy— K=¥ 
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mwir%mxhz> 0 

[g|23]Subset Difference (SD) ^aSfc&WSI^^HAf^fcol ^XWRlTZ 

mxhz> 0 

m2e]sDjj^z.^^x^^mm^mwir^y^mm^^^xmmi-m 

Xfo% 0 

m27]sDjj^z^^x^m(D^iBmu4^mi'^y^yhmm^^^xmm 
-tz>mxhz> 0 

[M28]j-wm^mm^^x^^ni<vm^v7*±yhss <DMf&miz. 

P(y), S(y) 

^^xmjii-zmxhZo 

1 2 

v b<DM)&&^1rmxh% 0 

2N-l 

imo]%im^mi-%7^<Dfcfefamiz^^xtmirmx%z> 0 
im2m%immN=i6\z.BfeLtzffim*mmz&^x. mtmus, uii, ui2 

m35mim^x^x'Mnir^^x^m^h^y'±yh^-<DWLn, m 
mmnwi-z>'7v-^--h%^-fmxhz> 0 

[H36]Rabin Tree^MLfcSD^Uc&l^T, gfl W^i^h^-^ 

mmw:<Dm^^^xmmi-^mxh^ 0 



WO 2006/030635 29 PCT/JP2005/015814 

14. Basic Layered Subset Difference v^LSD) ^ztOfES 

15. Rabin Tree^rffiV^c-<— >y^LSD^(D^-</^|iJ^1f^ 

16. General Layered Subset Difference (— $£{tXSD) ^StOHtS 

17. Rabin Tvee^m^z-m^LSD^fDy^mnMm^ 

18. Rabin Tree^jifflLfcSD^OBt^IBff If^&Jj-Sff JfSOgiJ^H 

[0065] [1. Complete Subtree (CS) ;^££>tllg] 

*Ti£#<©PWiiM7fc«^MLfc^n-K^-t^^^^yyi/3 V (Broadcast E 
ncryplion) ;fc£i:LT&JfbtlTV ^Complete Subtree (CS) ^"^(DtE^^oV 

[0066] ^T^PJ^fc^TK, ffi^^cfe^, ^ji»«3t^y-7^J^LT 

Tot&gmc&iv-c P«io g oEte-f^T2^fc5 0 P£JiM*#l^y-:7fc 

[0067] (1. 1) Complete Subtree (CS) ^^(DlK^ 

l^l3WT^#^UT, Complete Subtree (CS) ^<Z5$|^;:oV^M1-;5 0 
[0068] Ri)ji(^#WfT'A'i^l[ Advances in Cryptography -Crypto 2001, Lcct 
urc Notes in Computer Science 2139, Springer, 2001 pp. 41— 62TD 
. Naor, M. Naor and J. Lotspicch|lF"Rcvocation and Tracing Schemes 
lor Stateless Receivers"]] ^fBfc£tt/cComplete Subtree (CS) jjttVfe 

Sr#J!3^T5(S3{^t5ul~ul6) 0 *©#/-K(iJ)&/fl^-C\ r^oy- 
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[0075] mmmomimfe, ^^tKDW^^m^z.mh^v-v, i-&fr*>, ms 
K^-tmvn, y-K5, 7, 9, 12, mz.nv^xbfitz.j-Y^— %m^xm\n 

y<Dm^mmir%^^y*~Kcxhz>tu a-ks, 7, 9, 12, i6fc#j«^-t 

b^Z-K^-lrNKS, NK7, NK9, NK12, NKl6b1r%b, $^tM<£>}£{f # 

E(NK5, Kc), E(NK7, Kc), E(NK9, Kc), E(NK12, Kc), E(NK16, Kc) 

„ fc*5, E(A, B) tex-^B^A^Bf fftLfcf'-^^f *t5» 
[0076] ±fBBf^-fe^h«, M-^{f$|u2 ( ull, ul2(D^^-^-f§- ^TtT % 

[0077] %.mm&. mmntzm^xvyh. g^m^-et^^ -r^*^ &%mw 
^ce(nk9, Kc) %m%-f%zbtfx%% 0 :©^n, v#-?£tix^te\<^mm& 

[0078] (1. 2)CS^(C*3Jt5«i^BiJ« 

[0079] |3a6f^1-£5^> 7-Kj232^Tl^ti-?)fP^7jcP235^(y-7) £L 

[0080] rofc^ fc5y-K<^y-K^-£^LTi^{f», «fi/-K©;-K 

^-t>^i~5 0 /cix.«El6tc^i-j;5^, /-Ki231#V-Kj232<D^T*fc5£ 
/-Kj232<D/-K^-£&og{g*IG(u5, u6) 7-^23107-^- <b 



WO 2006/030635 



33 



PCT/JP2005/015814 



[0086] RSABf V ^tcttX*\Z, *gm±l/?<Dfy1>m$5&%C : d%m$5 jfe : 

M 

i 

NK =Kt1"5„ KGZ* «\KflM£Z* (1-fc;b*>, S¥Z ={0, 1, M 

1 M M M 

[oo87] M-h&L^(oy—\n(^)(Dmns wms-wm, 
mm 

NK L , /2J 



[#38] 

A^AT , = (NK [^ //2 j © H (/)) rf mod M 



M 
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M 

[0091] mtiSkfikD/— Kl(^/H (1 = 2, 3, 2N-l)tC^«{(gNV{i, K 
Bfc41] 

^ L //2J 

[0092] £T , TaSK-toT, tmp^^ai-^o 
[*42] 

fe/wp ; = (NV |_ //2 j - 77 (/ || ja/r /)) mod M 

[0093] ±iE^lC«toT^a$tlSi[tmp*S % ^Ufc2o<0;ktft£#<0ttM£fe£1-3 

WPJ^^^^i^^^/J^JE^salt^Eott^o salt «\ /-Kl(^) tML 

i i 

[0094] _bR'd5ttC*5V vT, l || salt «\ ltsalt Mg^gtU HKJ\ ttE<W^X<7) 

M 

^cr*fc5o -©^'tcBa^^ifcL-c, A;0fc:#Li6oifyHz>w;j£w 

l-Hfl^P^lictLTOSHA-l/^^r^iSc^fflV^T, |M| -160fcVh<D0^ SH 

A-1H1 || saltSrA^Lfctt^W^jSrtryHigjgLfe I M | tfVh<£>ft£H(l || salt 
i i 

f3\ A. J. Menezes, P. C. van Oorschot and S. A. VanstoneH, "Handbo 
ok of Applied Cryptography, "CRC Press, 1996£j|S^$;h/"TV5 0 
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[0097] 

M 

a 2 = K(modM) 

[0098] ±fe^j;5^LT, 
tmp eQR 

1 M 

i 

1/2 

tmp modM 

] 

[0099] rcOi^^LT, h^fjlNV frb. ^<D^/~ R2, 3tfV— K^filNV , NV £ 

1 2 3 

2N-1 

[0100] ^<7)J;5(-LTS^^tl^y-W(^)Oy— K^itNV (l = 2, 3, 2N- 
[$C44] 



^L'/2j = (^/ 2 + H ( / II ^ /)) mod M 



i 

[1(45] 
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temp j = (NV L//2J - H V II saJt /)) mod ^ 

• • • m^2) 

b. tmp 1/2 modM£j£#), 4o©#P©5*>OV^^ i *x KK^/V')©/— W 

j£{gNVi5t#)3o 
i 

5. Mfc, Hi, 2N-1{@(D | M | lfyHZ>^(/— K*frM) :NV , NV , NV 

1 2 

2N-2{@(Dic(y— K#M#£):salt , salt , salt 

2N-.1 2 3 2N-1 

[0103] m^JlENVdSRabin TreetfV-KlO^tfV— K*j-JM££5 0 fcS^ ^(U— 7 
i 

[0104] [£18^ ±HtiT^=f'!;XA(Dyn-^i- 0 7o- <&#*xy:/fc:ol^TlftBI31"3o 
[0105] ^7"y7 P S102{C*5V^T, SfeM^yf^gltgcH^r^fc^fC./V— IV— K<ZV— 

1 M 

[0106] Xf-X/SKMCl&lvC, ±RriLfcic^2(CjoV^TSa$^tmp^M^?iii-?) 

i 

i 

^7 l y^ , S105iC*5V^, tmp 1/2 modM^*fe, 40©)|0^©^fili^, 7 

i 

i 

[0107] ^yXS106^*3V^, 1=2N-1-C*>S*^^JSU 1=2N- v|§1^ 
HfTi-^o XT-y^S107lC*5V^T, l=2N-li:¥lJ^ti5*T:\ ^7 L ^7°S104, SI 
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1f^c^tLfc-^fB]7K^Rabin Tree£Pfr£ 0 CtUSRabinBg J§ri>K ft^fcimftfa 

mm (cmodM±© g mn. m^-im^mm t^modM±©/v-Ki/2H) inn 

[0112] fftfr*)* -^TRl^LTORabin TYeetfV— KlCRS$;h^y— K#^f2W 

&%\Z i gm±y#(D%-ft£M'e%Zo RabinBf -^O^Tte, fc£;itf±3£<£) 
A. J. Mcnczes, P. C. van Oorschot and S. A. VanstoneH, "Handbook 
of Applied Cryptography, "CRC Press, 1996£>pp. 292-294(Cf¥LV^ 

# txorj t?iR#ifex.Tt > «tv \ 

[0113] (2. 2) Rabin Tree£fflV\/hS^<Z>8lJ^fifc 

±Rrf^«fc5l£l*JiJcL;fcRabin TreelCjoV^, CS#^£|^{C;fcO#y— Kf£*fL 

i i 

i 

NK = He (NV ) 
i i 

<b-f 6o fc*3, KH&Hcfi, iMX I M | <D{g£\ ^Xc^v^&jg^^-f 

bit(7)jii:^ai^J-r?)[^iC^LTfi±iecOSHA-l^fcf9, C^i28bit<DJll=h 
ft^Of--l , XOA^^^L128bitOffi^(Hyj-t _ ^ll^tLTfi, MD5ftWfrl£>tl 

t*30, z.tib<Dmm%mm-r%zttfx*%z> 0 &*3, mds^ov^, i^oa. j. 

Menezes, P. C. van Oorschot and S. A. VanstoneH, "Handbook of A 
pplied Cryptography, "CRC Press, 1996tCf¥LV^^d s fe5 0 
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NV =((NV ) 2 + H(9||salt ))modM 

4 9 9 

4 2 

NV = ((NV ) 2 + H(4||salt ))modM 

2 4 4 

2 1 

NV =((NV ) 2 + H(2||salt ))modM 

12 2 

[0119] $^^,#y-K©/-WJS^^y-^-^T^^{CioT^WT#5o 

(bi)y-Ki9<7v-K*fj£fifi:Nv a>£>/— Ki9tfV— k^-nk 

19 19 

NK =Hc(NV ) 

19 19 

(b2)/-K9(D/— KttJCMNV d^y— Kdf— NK SrlfW, 

9 9 

NK =Hc(NV ) 

9 9 

(b3)y-K4©y-K>?fj£{i£NV MtfV—K^—NK StDlW, 

4 4 

NK =Hc(NV ) 

4 4 

(b4)y-K2©y-K*r^flSNV /^/-K2tf)/-K^-NK Srlfffl, 

2 2 

NK =Hc(NV ) 

2 2 

(b5)y— Kl<7)y— K^flSNV ^/-Kktv-R^-nk £Jltfj, 

1 1 

NK =Hc(NV ) 
1 1 

[0120] h^X\ Sfs«u4«, y-K^jfiNV }«£^WLT&X£^fc5/6\ # 

19 

[0121] ^LT\ #y-KfJ^ll^i(salt(75^-rX^^^6 0 $>5^SteM<DTTT-*PJ^^ 

^»^}»l/4-X?fc5fe«), salt £LT4o<£>1j&£:g£?-^ imp tfW-jjffl&kftZ 

i i 

i 

[0122] 4^<om<D^i?tih¥ : %n£\tttt^m&hh5o tct?uf;-mnm 

ftsait kLXLm<DW£&Uzk%. tmp ri^T ^^PJ^ftW^^PJ^ 

i i 
fc5)?t^}i3V4 L -efe5^:it>,L=4©^^«, 3 4 /4 4 = 42. 2°/o©|$t^f 
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, S{fium(m=l, 2, .... N)&*<D&mV-7)lZ&*)%XZ> 0 
[0126] b. 7fry?2, 

fSty^ (TC) *f , ScMtDIMX I M I £^&5 0 

[oi27] *m&<Dmv-7)mi. wmwjx i m i %Aijkvxm^\ ms<D?v 

— &&MLXffiW\JzTJl'=fyXJ*lz:$£<>X, N$<D^£#o2#;fc<£>Rabin Tree 

M 

1 M 

2N-H@<£> I M I \fyY<OWU—Y^M) :NV , NV , • • •, NV t, /- 

1 2 2N-1 

K2d^y— K2N-llC*HSi - 52N-2te<^j»:(y— K#*P^^[) :salt , salt 

2 3 

salt ££#)3 0 saltf^^Tte&l WSHrv^ (TC) tfS£;h,e><£>flKr&BBL 

2N-1 

xt>£\\ *tc^m±^?(Tc)femMk^yt°^mmi% / £mirz>. tit. imx 

[0128] ±fBM^j;oT#y-K<D7— K*fiSfl£NV Sr^«)fcRabin TreeOfl|j^^5fe^ 

i 

^i^^$n^(i,fc^y-K<DfieNV^J:0sait^^^(Dm/-Koy-Km 

[0129] ^m±y?(TO it, *<ds— ki(^)<7V-k^— NK^y-K^ffiN 

i 

NK =Hc(NV) 
i i 

[0130] c. XrryfZ 

^m±>? (TC) tt, KtLTOg \ZM^XWL^M^ 

|um(m=l, 2, NMCfctU £XT(D/U-Mzm^^X/— K^— £-£&5 0 g{f 

ttttt@ 10^1-^5 (y-7) N i-/^^y-K#-^i6~3i ^Tbft 
TV^c EllO^I-^J-Cfi, gfififcB:* /-K#-^-16~31^fiJi9^T^tlfeul~u 
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lOt^m S^»um(m=l, 2, N)£«)^||(y--7) 

[0140] &^x;y:7°S 202^1/^ OTHr^CrOf*. SMWf^X | M | £^&5 0 

u 

©H^tC-ryfc'^i- 5BISfcHSr3tfe, Nf@©^^o2^7tv(DRabin Treelrff fife 

1 M 

I M I \?yb<DWcU—h*ftl&W :NV , NV , • • •, NV £\ /— K2j&>£>/— K2N 

1 2 2N-1 

-l^^-TS2N-2fi(7)^:(y-K#i}P / ») :salt , salt , • • salt 

2 3 2N-1 

[0141] f=a-feV^(TC) J3\ 7fc(Z)y-Kl(^)^/-K^r— NK^y-K^jEN 

i 

NK =Hc(NV) 
i i 

[0142] ^yy°S203\Z.m^X, *gm±>? (TC) 7K^*jJS/— KtLTOH(y-7) [31 
#J&LT^£;h^{f«um(m=l, 2, N)fc*frU M&Ltcf—? , 1r?3;frh 

•v 

(a) %imum(Dm ^ T^Hfc^Z-K C^/~K*J-^1i£NV 

i 

[0143] (3-2){£«fi{g*i 

^$rat -tzztfrXoxftztiZo zivetuDv&tttes mmm%;-b**-<D 

mplete Subtree;^ (CS#^) Mttt^3i>5 0 
[0144] 7ttxLffg|5^L^:M-e{^ 5otf)B£ -^£^j£{f $*t5 0 05l3l^f ^J"CttS^ 
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[0151] ^ 5 /7 P S304tC*5V vt, S&Lfcy-^-TS^^Sl&Sff $fi£fl§ ^ffcU 

[0152] Bf^^Jffli-Sy-K^r- tS-fe^ (TC) iS-feyhTy^axTXtc: 

i 

[0153] ^\ y^-yi-^f^&v^i^m, /i^-h(Dy-K^-NK &mmnn<D 

i 

'ho 

[0154] (3-3)t»«^fS*3«trm-f-«!-3l 

mummz.M%ismiz&fc£ti5o hz^mmtmmm^mnxmm^ 

WX-giEtif ?s%ftt£?ZktfX$ft\, \ 
[0155] M-^&ftTV^vSfglf fl, %mLtiV&FjX<D±yh1>*t>a d#tB 55"C*§5fl£ 

1 

[0156] y^-^^nXV^V^ftatt^ S—FMJ&feNVt. saltan Bf -^Wcilffl^ 

1 

k k k 

k 
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[0160] ^ffif$R&[Kc]£*f E(NK , Kc), E(NK , Kc), E(NK , Kc), E(NK , 

12 4 9 

Kc), e(nk , Kc)<D\,^'ftii!)*$r£t£V&J$rX'te-yhitK ^yhu—^Mith^^tm 

19 

7\j— K4[PathNodes-4] = {l, 2, 4, 9, 19} K#-5§-£— SH"5& 
[0161] 7— K^r— NK , NK , NK , NK , NK <T>\v?fohK Bf 

1 2 4 9 19 

g B<D{S^i-5y-K^fltNV £\ ./-RttiPg^salt , salt , salt , sal 

4 2 4 9 

19 

NV =((NV ) 2 + H(19||salt ))modM 

9 19 19 

NV =((NV ) 2 + H(4||salt ))modM 

4 9 4 

NV =((NV ) 2 + H(2||salt ))modM 

2 4 2 

NV =((NV ) 2 + H(l||salt ))modM 

1 2 1 

[oi62] ^/-K«;-Ff£i^?);-^-^ 

NK =Hc(NV ) 

19 19 

NK =Hc(NV ) 

9 9 

NK =Hc(NV ) 

4 4 

NK =Hc(NV ) 

2 2 

NK =Hc(NV ) 
i i 

[0163] Sifau4te,/W-K4[PathNodes-4] = {l, 2, 4, 9, 19} fc'g'&h/S/— K 
tfV— Kdp— :NK , NK , NK , NK , NK 0)1 fti&vSrigfflLT, Bff#X"feyh 

19 9 4 2 1 
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ra«&3&«410ra:, -^fn]7(c (Rabin Tree) £$^©411, /-K*-£$^g! 
412, ##tff #(/-K*f^ffi:NV, y-raS: salt) jfe£#©413, B£^££ 

[0171] tum&mmmm^ mm^mmz.m^<y^-v^^^wyB^^ 
i-^m^mni-^n^mmmxm. (Rabin Tree)^#^4ii 

Lfe— ^■[R]7fviLT<DRabin Tree3r3£fi£-f5 0 
[0172] K^- ^fife¥S412tt, /— WJ&fiBsrVfcS-^T, 

NK = Hc(NV) 

[0173] #t^^^^413tt, P§Jg7|c©*«gy-K*rjS©Sfi«^, gfH«*feStfV 

[0174] Bffo-Jt^ricT-©414H:,— *lR]7fc (Rabin Tree)£j&¥l£411<D£jjJtLfcRabi 
©4 1 2^£/&Lfc/-K^-NK£jgif^ {Cjgffl LTBg ^fb&aSrHtrLTlif 

[0175] |^l6£#J!«LTPff5-A-om^^^ 

[0176] B£ °^fl.^^Tl-?)S:fMiLT(7)t^^^a^i^420tt, Bt^-Jtii^ 

^-S421, A-K*-#fcH#a422, m^M£423, ^)A2A^^ 0 
[0177] Bf £-«#^j£421 ^a^t«Bt ^O^b, I B^^!J424(I^i-5 

i 
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[0182] ^^\^mtmfmw^^^mmi<Dmmt^mm^mm^it^<r4¥'M 

NK e modM 
i 

[0183] RSAm^W\mLtc^ : rM^^X\t, ftr%.m<DfflU<Dtiib, &BB*t!&e£fc5 
e = 2 16 +l 

[0184] ^H^i:eiLT2 16 +l<hV^fe^fflV^^, fc5&xtf)e^£fr£;frifcfiVKoj&> 
&>5^\ rg^^#(DT^UX^j(tu^A. J. Menezes, P. C. van Oorsch 
ot and S. A. Vanstone^t-, "Handbook of Applied Cryptography, "CRC 
Press, 1996, p614#J8)iS:ffll\fc#£\ 160^ g^|^l[H}(D^5f«,g^ 

T/h£<-e#5fc«>, ±IEOtf-||tfittgm*17|ll^«tf3f>^:t<*5 0 tLRSA 

f^^fflWc^jUc&^T, ^j : lii:eiL-C3iV^5'^^S^fflV^^#^T^, NKmo 

i 

[0185] CtUC^U ±$U^3£^Rabin Tree£MLfcCS;?7^J;»^CSBff 
^JcT^ gisTO, 0 B(D^-r^>/-mJtMNV\t, /-KttMftsalUcS 

[1(52] 

NV lJI2] = (NV } 2 + H (I \\ salt } ))mo<\ M 
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®H6tfHg:Yez* 

M 

1 M 

Z* ©5c-efc5ii:S:jgc5lc*r5o 

M 

[0191] m£MW~<D/-m^) (1 = 2, 3, 2N-l)^m-r§fi:NV«, %<D/—h* 

1 

[*53] 

[0192] *-f , TzU££oT, tmp^^i-5 0 
[16:54] 

teinp , = (NV Ul2 ,0 # mod Af 



[0193] ±Rri^(-«toT^$tL5fi£tmp #\ MSrajt-f S¥-^PJ^(^S«t5^^J^iH 

^icsait^ao(j-§ 0 saitfi, /-Ki(^)^^;LT!^^$^y-KfJ-Jii^ic-e 

i i 

[0194] ft3b\ ±fB^(-^oV vc, H{2, ftjtO^X(DA^SrMi&L^:2oW^:f Jfe^ic© 

1 

saltl = 3 
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NV L;/2J 

[0198] &mMmzttffcir%m^mXfo%2ft^<DR a bm Tree&mf&irZT/VcryXJ* 
^M^lMX: | M L 

cm*] 

2N- lfglO | M | fcVh<£>ic(/— W/SlitO :NV , NV , • • •, NV t. 

1 2 2N-1 

2N-2B(Dmy—VHM^W) :salt , salt , • • •, salt -Cfc5 0 

2 3 2N-1 

[0199] JbfE^EA^Dfcl^T, ±gBO[ffl^]*#5r/i'^yXAtt^TO«t5tJ:*5o 
1. 1MX | M | /2020(D*tfrmfc££^ ^OaM^f+^-T^o 

1 M 

3. l(x^)^r)y^itt2^^2N-l^lfo^|I^^^TRiia, b©M 

a. Tfi'ri^ 
[fc57] 



few/? , = ( NV I //2 I © H 1 (/)) mod A/ 
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i i 

Hfc58] 

*##>Z>z.b\SM&,1£'&, Z<ommW*£kv>bt£Z> 0 

[0206] ftfCtaiflUbt?^ El9^joV^T, r^f^^or^^TV^it^PP^ 

1 

i i 

[0207] H9^*3V^ mm~ l W^X^foX\^mk$:m-$. ±.tiL/~-h*<Dy-h*ttJfc 

m%A-jdb\.xrmr 1 %mm~t%z.bx\ r^y-voz-m^im^ibhti^b 

[0208] r(Dj;3(-y-K^fiSNV{iT{v.*^±{v.O-^|nj^O^T«, &$?£;fc,fcKlgC: 

1 

#|j&£nfc-^ft*£Rabin Tree ^SRabinfl^^ Bf^kOl^lR] 

$80 fCmodM±<7) | ff|^ m ^(i^^fp]^) ^modM±tf)/V— h (1/2^) 

[0209] 1rftt>h* — #lR]7fc£LT<E>Rabin Tree<£>y—Rra^£tl5y— KM^'fE^W 
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[0212] Rabin Tree*|^J2«, 5fcf^ Hil7^»LTl^PJ!L^a->-^^^oT 
o Kfctt, I M | \?yh<D%cV—\?ftfi;M) :NV , NV , NV tA/ 

1 2 2N-1 

— K-H-jto^fc) : salt , salt , • • • , salt tfttfctttfbtlZ> 0 fe^y-K^ffiNV *5 

2 3 2N-] 1 

i 

[02i3] if a-fe^ (to ^mmum^nu 

i 

i^salt«^^feiLTj:V^f[fi:^fe^,^(^^5riM^gT1^V^ 0 
[0214] r^yhTy^^-^^tt^tlliail^MLrKWLfc^ffl^-^^i 
IrJ=BIT?4)5„ KSi"5Rabin TreeJ&Sfltf3£tf>[5. Rabin TreeHtjj£#|2£jl 

fflbfcCS^<^#fM)c] IddoV ^TfMUcRabin Treelf/#£ft5 0 
[0215] (6-2)m : MEfsW. 

[Sl^i^fs-rS^I-ctoT^tt^o w^fttffltt, [3. CS^IdRabin Trccflfj£ 

#j i ^iiffl t» 5- is ° w.] ^js b(3-2) ^mm{B^mzid\, ^xmw 

X9$%-4kLtz.h<DX*hZ)o m^it^mirW-^-OmiRljmt, Complete 
Subtree^ (CSjj^O bW\W.X&Z> 0 

[0216] tz.tx.\tm5\^vtzmxn, sm^xtfmmtiZo gis^-r^i-m^ii 

mu2, ull, ul2^y^-^$n5^fs«T?fe5 0 1"*fc*>, Sfl«fcu2, ull, ul2£ 
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[0222] vtf-fztix^ft^&mmft, &nuzi&%xo±yhi!>*ib&&&Gi%-e%m 

i 

[0223] v#-?£tix\s^^mmi%. /-mmmNvt, saltan m^timm^ti 

k k k 

k 

[0224] r^^^ltf^S^&l^ Sfflf umte, Bf-^>fk(C^fc>n^:/-K^-<?D/- 
K#f-k£JAffiU aum^J^-r^/^/-Km[PathNodes-m] \Z$$#lZ> 

[0225] gff lumll g #^§W ^ T^tV^l (^) (ZV-K^^NV £{£&LTl ^ 

] 

mm 

NV lll2] 

mm 

NV L//2J = i 2 © # ' (/)) mod M 
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[0229] ££>m, frS-b'toS-h'ttfom^bS—h**—*. 
NK =Hc(NV ) 

19 19 

NK =Hc(NV ) 

9 9 

NK =Hc(NV ) 

4 4 

NK =Hc(NV ) 

2 2 

NK =Hc(NV ) 
i i 

[0230] gfS$Su4kJ\ /W-K4[PathNodes-4] = {l, 2, 4, 9, 19}l^m5/-K 
0V— Kdp— :NK , NK , NK , NK , NK <D^-f tl^MLT, B&^-feyh 

19 9 4 2 1 

(I^^»^J^IfUS*ffi[Kc]^^^#^5 0 
[0231] g<a»um©&SU::oVv-C Sr#flgLTlft^i-5o £T % *tWS4 

[0232] *x:y:7 0 S452^:Jol/vt, ^LfcRf ^£<Di?yM^;£ft58g ^©ffif-g-ffcteffl 

v^Ti^y-K^-^^fb, S#^ii:^^tTv^/-K*t^itNv, a-k 

[0233] ^y^S453(^*3l ^T, B§ o-ftfcffifflSftfcy-K^— D ritfSfttH- 

5/-K*J-^ffiNVi:, y-KfJ-ai^iCsalt^iifflLT^0Ji-?> o Wte, ml^O 

NK =Hc(NV ) 

k k 

k 

[0234] Bt^b^^^fcy-K^-^^ttl^tbSt, *7^:/S454Kii#., £fflLfc/- 



WO 2006/030635 



69 



PCT/JP2005/015814 



[ic62] 

temp j = (NV , //2 - 0 // ' (/)) mod M 



i 

, H^l0ff#1-S©M^0#^tt,fii^(7)^i (Rabin Tree^£0j|l) l-Jfc'* 
l/2T?SFip 0 HtfTs¥^m%ltit)-f%t-ttlU, tmp eQR 

l M 

fe^tl^tKDsalt \Z.ttVXm/4b. MftOfife (Rabin Tree#|j#$Jl) 

[0239] [8. Subset Dif f erence (SD) jf&i] 

±.&Ltz.%±mWl%, Complete Subtree (CS)^(CRabin Tree&iMfSUttlk 
mfilXhotctf, ft {31, Complete Subtree (CS)^^^5 Subset Differen 
ce (SD) ^iS^StLTRabin Tree^igffiLfc^SW-oV ^f^-fSo 

[0240] ±!E<£>£5^ Complete Subtree (CS) ^5U£&V ^T{i, PgJl K (fin) 

&5££\l££LTl^fco ^tlt^U Subset Difference (SD)^^*3V^Ttt, 

^*<D2o^y-Ki, j(/cfcU(ij^5tm^fc§/-K)^fflv^T, ny-F&w&k 

1-&$#*^y-7(^)^ib&^^ 

[0241] fcfc, ^T^M^fc^Tte, TIB©IB#SrfflV^KiKi-«o 
P(i) KM>a^-K:fcJ;tre©y— K#f- 

S(i) : y-Ki©ill& (sibling) -e*>5y—K(i"^*>, KT\ iil^CH 

LC (i) :/-Ki^£IIiJOT/~K:feJ;U^<D/-K#^ 
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[0248] 022(B)©ia^"t"«t5^x LABELi = S£, CtVhA;^ 3Ctf$/hfcH;fr<£> 

(llEi^ ^fc^ftG (S),G (S),G (S)ir-r5„^LT,G (S)^El22(A)iC 

L M R L 

R 

[0249] l^, r<D^a^«t«9, m22iz^xy— KiO^ftlOT-TffcSy—Kk^oV^, 7 
— Ki^^(-L/c#^<Z)7-Kk(Z)^/VLABEL LABEL =G (S)£ftofc 

i, k i, k L 

o -tL^Tt*5<o ^^^y-Kk(Z)7-</^LABEL =G (S) =TS\ 022(B) 

i, k L 

L 

T),G (T),G (T)^,^tL^^T<^J;5^^i"5o 

M R 

G (T) =y-Ki^^J-L7im-^<7>/-Kk^ftij(Z)^-y-KLC(k)(Z)7^LAB 

L 

EL 

i, LC(k) 

G (T) = J— Ki£*& \Z\JzM^<DJ-YWm dtlfc^S i^JSfSt^ 

M i, k 

i, k 

G (T) =7— Ki^^^L^c^©/— Kk0^ffl9<D^/— KRC(k)07^LA 

R 

BEL 

i, RC(k) 

[0250] r©*afflSr»5gi-rt^J:0, y-Ki£*&£fcUi:»£^ tttthiX&r^X 

-efct), 7— Ki4:*&^i:Lfc4&^^, 7— Ki(Dm&^h<DlttmxhZ>tztb, LABE 
L^iaSLic^^GfcA^Lycai^^^^^fe^G (sm{£;btU£l^k: 

i M 

[0251] m22(A)W[|T^1-^, FXDy^Stffelsbbtl, G (S)^y-Ki 

R 

^^^iL^#^0i(D^(DT-/-K07^^^^^^^^tt^MSL^^^G 
(CA^LT#b^G (G (S))#\ 7— Ki«r*&AtL/t*^©y— Kj©7^LAB 

L R 

i, j 
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Z>y-?±yhXhZ> 0 

[0257] tfts y— 7utt, y-Kc<D7^LABEL iC^<»(ai^»G<D^3l^J; 

i, c 

i, c i, c 

G (LABEL )=SK bftZ> 0 

M i, c i, c 

f-r/iryhs 023(c) ^^5^^ /-Kc(y-7 C )^y#-^«iLriS 

i. c 

[0258] m£&k~f%mmM^^x, y-yuziw-m-^M-t-rznm^ ^tih3 

O^tti* I2£ FT^-CfeSo ^!lx.filH23 (a) <DV—7d251(Dfy&})tf—?ft%i 

i, d i, d 

l©ysK— ^^*M£i-5f-^-feyh^-SK £\ y— 7uiSft^r-f-5/— Ka©7^L 

i. d 

ABEL mS^V^^RTil^JfcSo 

i, a 

[0259] -^^(Df-y-feyh^^oV^P^T'fc?), 023(A) ^^5^, fo^in 
tttutt . ^rtl^tM ^ XbtltcV-7 (H) frb*<Dm&^<D/*x±<D*:ti?ti<Dftn 

[0260] m24it±^immN=i6(Dm^(Dm^^im^mnir^y^;^^ir 
mxh% 0 mmuA^x.^ ^tii)mmxbtitz.y-7m)xhz>;-\ t 

, 18©4-oT*fc3fc«>, SisIu4(i4o^7^, -J-ftfr^ 
LABEL , 

1, 3 

LABEL , 

1, 5 

LABEL , 

1, 8 

LABEL , 

1, 18 
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[^64] 

\ogN -I i 

l+£& = -log 2 N + -log7V + l 

[0268] #g{ff««, ±IB^^J;oT^$tL»^7-</^^L, ^£tLTV^j«gL 

[0269] [9. SD%&(D^/l&fflWm&'] 

Subset Difference (SD)^^7-^/HK©S'JS£*fifet!:oV^SiW-f5o ±3£L 
fcSubset Difference (SD)^*«^i-5i, &T<0£fca s fc>J&»3o 
[0270] -f**?*), 7-^LABEL ft, 

i, j 

(a) mmimm, <gm±y? (to ^b^bn^m^-t, 
(B)^im^ti^(Dy^^bmmm^^G^m^^xmm^m^t. 

/-Ki£/-Kj^$i7-0|^(ff^ 
[0271] *>5^{f«*SLABEL ^MSL^^G^fflV^<9HJl-^i6^^, 

i. j 

i, k 

LABEL fe¥(D%lnm^h^btlT\<^^tc£>X*hZ> 0 

i 

[0272] 025©«^J*#flabTlftKi-5o LABEL ft, g{f »u4fcfiJ:ifflg, fJffi-fe:/ 
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i, « i, * 

[0279] 551*5, Rabin Tree£j£ffl-f S^^, x^£>y£f+^-f 3<D (Jl I^ftOffl?-) \% 

^^^mx=F _1 (y) pTH»-*5o 
[0280] ^-y^/KOSD^Tftt, ll24£#MLTf#^LfcJ;5^ g{a#Su4teff-llf@0 

i=l^*J-LTj = 3, 5, 8, 18<7)4o©7^ 
LABEL , 

1, 3 

LABEL , 

1, 5 

LABEL , 

1, 8 

LABEL , 

1, 18 

i=2^*fLTj = 5, 8, 18(75300^/1/ 
LABEL , 

2, 5 

LABEL , 

2, 8 

LABEL , 

2, 18 

i=4^*fLTj = 8, 18(D2o<D^/V 
LABEL , 

■1, 8 

LABEL , 

■I, 18 

i = 9 IZ #LTj = 1 8 (7) 1 
LABEL , 

9, 18 

!^~^ftL<D^ffl<£>LABEL£lo 

LABEL , 

i, * 

LABEL , 

1, 3 
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[0284] Z(DX^B^n^y-^n^NV{Z^m^tl±^Rabin TreeW^o 

i 

CftteRabinHf-^ Bf^b(I«^]^^)^modM±(Z)Smm, U^(M.Jjfa& 
W) ^modM_h(D7^-^(l/2^)^^^fflV^TV^^fc:fe•Cfc5o &*5, Rabinfff-^ 
fcol^TteU ftk%.\t±M<DA. J. Menezes, P. C. van Oorschot and S. A. 
Vanstone^, "Handbook of Applied Cryptography, "CRC Press, 1996 
Opp. 292-294^PU^PJ^fc^ 0 
[0285] J^T, Rabin Tree^ffiV^cSD^(D7^»JM^^oV^, PiB^^ 

[0286] ^pjrai, y-Kiiy"Kj^^-r«(»i, i-^^^j^-rs^^fes)^ 

i, ) 

1, * 

LABEL dttl/C, Rabin Tree^ffli-5r^^±0^*^{!j»t"59^j»[ 
[0287] |^®7K(cSa$^1--<T(7)f-^-fe5/hS <DfT\ /-Ki£/— Kj^ii^M 

Special Subset) SS ^ai~5^<*:1~5o 7|ctfX^— 

i. j 

i, j 

1, * 

1, <*> 

[0288] ^lWJf-^-feyhSS ^*J-j^i-^y-</VLABEL (j = 2, 3, • • •, 2N- 

i. j i, i 

DCJtLt, ^PH^A- (Intermediate Label, IL)IL £)^U 

i, j 

^/hSS fcfcj-LT, 4^7^/WL ^SIt5 0 
i, * i, * 

[0289] &£>l^ ^^O^^^/^-h^ORabin TreetfV— Rx^fgNV ^J^fjlt 

i 

§ 0 i-ftfrhs 
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[0292] y-K^-fi^r^^/^V^-^ ( ^f^f^^Mff1-^tft#OBt^b^ffiV^^^^ 

\/\ fc^X.fM-^T/^yXAiLT128bit||(DAES (Advanced Encryption St 
andard FIPS197) Srffll^S*^;:^ C&128bit£-*-;h,tf«fcl\, 
[0293] El28(C^^^0i|^i- o g|28{C^oV^T, Kj551tCtt/-K*fJS^LT© 

j 

[0294] 7-Kj551(Z)my-K«, P(j)552T*fe«9, jZ.il/-KttS 0) 553X*&% 0 7— Kj55 
1<DR%/-VS (j) 552^ fe£tlZ>$£l<D&W£y-'7±iybSS 

p( 

tt, [H28^^-rf-^-fe5/hSS 550Xh& o 
i),sa) P(j),SG) 

[0295] r<7)^\ f-^ir^bSS 550{^J^1-^7-<^^, LABEL 

PG),SG) PG),SG) 

LABEL ^.^my^/^IL (^iXiiy-Kj5510/-K>PfJ^fitNV^ 
PG),SG) PG),SG) ~ j 

LABEL =Hc(IL ) 

PG),SG) PG),SG) 

LABEL =Hc(NV) 

PG), SG) j 

[0296] 029 {^w^^wtm^x>t^h^m^\mm^^mm&^ts 

±foMzMfott%2(D!fcW£y-Zf'KyYSS O^A-LABEL t, (b)/— Ki 

i, * i, <t> 

i, j 

= 2, 3, 2N-l-CfcS)t-*tJ.^i"57^</l'LABEL t(D^.^f—^Xh^ 

i. j 

nfl^MlL) £LTtfV— K*t&fi£NV <BiHj£*!fcS0fl£>j<-t"o 

j 

[0297] lg]29^fcV^T[i NV 

k 

NV =IL 

k i, j 

f?!l^(f[l NV 2] ft, 

3 

NV =IL 

3 1,2 
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4, 8 



2, 5 



NV (=^f|7^/WL ) = ((NV ) 2 + H(9||salt ))modM 

4 2, 5 9 9 

(a3)/— K4©y— KMJ&fCNV (= "ffi^/WL )^£>±&y-K2tfV-KM 

4 2, 5 

J^NV ( = ^^7^WL 

2 1, 3 

NV (=^ra^/HL ) = ((NV ) 2 + H(4||salt ))modM 

2 1, 3 4 4 

(a4)y— K2©y— K*flSfiNV (=tf , Hl7^HL )i&>t>±&y-KltfV— KM 

2 1,3 



1 1, * 

NV ( = tfJ fg^^HL ) = ( (NV ) 2 + H (2||salt ) ) modM 

1 1, * 2 2 

±E^^S^X^#i-i^,T{iy-K^/-KM^^^±f4y-K07-Km 
[0303] KtfV—KMJ&iU tpffly^Mfrby^fr (label) ^^toSI: 

(bl)A- K194V— KMfSffiNV (=4T^7^</HL Kl905^<ML 

19 9, 18 

ABEL )%9f.m, 

9, 18 

LABEL =Hc(IL ) 

9,18 9.18 

(b2)y— K9<D/— KM&flgNV ( = ^my^^lh )^/-K9<7>7-</KLABE 

9 4, 8 

l )%nm> 

4, 8 

LABEL =Hc(IL ) 

4,8 4,8 

(b3)y— K40V- KMJ&4ENV (=TO^-</WL )i)^—h*4<D7^</U(LABE 

4 2, 5 

L )£#0L 

2, 5 

LABEL =Hc(IL ) 

2, 5 2, 5 

(b4)/-K2(Dy— KMl^fiNV ( = tf>iaj7^</HL )^/-K2<£>^</V(LABE 

2 1,3 

L )£#ai, 

1, 3 

LABEL =Hc(IL ) 

1,3 1,3 

(b5)/-Kl<7V— KMl^NV (=4T^-</WL Kl©7^^(LAB 

1 1, <D 

EL 

i, * 

LABEL =Hc(IL ) 

1, * 1, <P 
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[0309] (11-1) ±y YTyf^M 

[0310] -tyVTyZfti&m., £XT(DX7 L yy p 1^4<Df&m\Z^XMft~t%o ^T^Ko 
[0311] a. ^f^7°l 

*1\ wa-fe^(TOtt, 2ft*x%mimv~7m)*w^mm*%mmi-z> 

^1-»SiJ J fiLT,k(k=l, 2, 2N-l)&R^5ofc;£L/V'-H£lfcU 
J^T, KfcoVvTJgifc, *g^3fe (breadth first order) T\ WJ^- 

#4^t5o 1"fc;fc>*>, 027^i-J:5^/-K#=^-(y)co^^^T^5o i©«katc 
«t!92^ I t , <^#y-K^y=l~2N-10/— K#-^-«^$tl5o 

[0312] 5fllum(m=l, 2, N)^<75#||(y-7)(C#J«3^T5„ H27W!|-Cte\ / 
-K##y= 16-31 (C^{faul~ul6(016^(Z)^{I»tiJf9^T^^ o 

[0313] ^^#F*3^/-Ki(i=l, 2,'", N-l) fcolv{\ y-hWH6"CS>5y— Kjfc 

i. j i. j 

■r/Uf-^-feyh: Special Subsct)SS b$ttZ.k\ZL'tZ> 0 Z.Z-V s *<D/l>~-b$:f(k< 

i, j 

#A-KH\ ^fl^^m-(D%y-Y-%:n^(OX\ SS £>jfc:JiJ = 2, 3, 2N 

i. j 

-l^Sj^cfcl^ToCT$ti§^^m$tt/cV\ Utf-^-TSgfUi 

1, * 

[0314] b. 7.y-yy°2 

tW^* (TC) i*. £f\ &M<7)1MX | M | (0!l;ij£lO24bit)£jt«>5 o 
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1 2N- 1 1 

j 

pG),s(i) pa),s(j) 

NV=IL 

j po.sa) 

**5, PO) tty— KjOlR/-K-C*)l9, S(j) tt/-Kj<£JLH/-K-Cfc5o 
[0320] LABEL ^Fl7^HL (^ti/— Kj551©y— K^j&llSN 

PG),SQ) PG),SG) 

i 

LABEL =Hc(IL ) 

PG),SG) PG).SG) 

LABEL =Hc(NV) 

PG),SQ) j 

[0321] ±fBtf>#yffi£olvC, SlJ^^i-Hff, Rabin TreeOy— K^tJSffiNVi:^ M 

IL =NV 

i, * i 

£fcj = l, 2, N— KCxtLT, 
IL =NV 

j,2j 2j + l 

IL =NV 

j, 2j + l 2j 

i, j 

^Iffl^^WL ^OT^^oT^OiU ^-miJf-^iryh^xt^1-^7-</^L 

i. j 

ABEL £LTEx/E-f5o 

i, j 

LABEL =Hc(IL ) 

i. j i, j 

[0322] c. Tfrv-FZ 

7*±yhSS ©7^LABEL SrjUHaftififeSGtA^U /-Ki£#6/£iL/c:, 

1. i i. j 

KjO-T-y— KO^^/P-LABEL LABEL £*#)5 0 

i, LCG) i, RCQ) 

[0323] -tt£t>hs tVhifcCOLABEL ^MSLM^G^A^jLT#e>tL53CtVh 
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mz?£-oX\s^Ml<D¥?Wj:y-y±yhSS <Dy-<MX LABEL .LABEL ,L 

j 1,3 2,5 

ABEL , LABEL O4o-efe£ 0 

4, 8 9, 18 

[0329] mmtis* (to fi, itbfeofi3s^7^o5*>, i&mjtni&£&Wh2<Dm\ 

[0330] £^ Mi^crcm, S^«tm, *©S«»ss«9^-cfeixTv^y-7(^ 
) jO^y-KP (j) Ztetitu WftftS—h'S (j) t-*|-JS1-5^J*f-^-feyhss 

PG), s 

(TO gf&«u4te, il (=y-KmiNV )£^x.3o £ft»*£*.e>iT,fc 

[0331] 1~ft;b^ £1\ gfi filu4^0i6Ji?©&57-</KLABEL) fcl/C, LABEL. 

i = ltC^-LTj = 3, 5, 8, 18 
i=2^*fLTj = 5, 8, 18 
i=4K*j-LTj = 8, 18 
i = 9(d>(tLTj = 18 
y^-^^L(D^ffl(75LABEL^lo 

[0332] ^(Diim^umtRy^vfrh, mm^tz.mi^xim2(D^m\^y^y 

Uy^^'ff^h^y^-^h't^o -tttfb%, LABEL <Di, ]<Dm&£Xr<Dh<Db 

i, j 

i=l(-*fLTj = 5, 8, 18 
i=2{ZMLX] = 8, 18 
i=4^*)"LTj = 18 

TO^/wl (=/-k*J-^nv ) 

9, 18 19 

[0333] ft3b\ ±BmX^Ltc%imu4&ft<Dm<D%imum\Z.3o\,^r-b, 4-X.bfhZ>7-< 
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[0338] ^fc\^-e^i65^f|7^/Ht 

i, * 

i, j 

i, j i, j 

i. j 

LABEL =Hc(IL ) 

i. i i, j 

[0339] m^Ty^S505\Z.^X, ^Wzf±iyhftJ&Oy^MZ&<5^xmW7'± 

yh#^(D7-<^^ttli-?)o 09x.ff . ^l^WJW^'fes'hSS Oy-^LAB 

i. j 

LABEL K LABEL ^flb^^m^WO^LW^X, WtfeLtz 

i, LCO) i, RC(j) 

M 

[0341] ^^S508(cjoV^, PS^7Koy-7(c^£,;LTES!:^tl5#Sfg^^i- 

mut^m^<Dm$R<D2&mfcmti,x'Mft£tiz>o 

[0342] 1-ftfc>*> , £1\ g{f ^um^O&^foS^A' (LABEL) irLT, ^"U v^A- 

i. j i, i 

±IE©^2(D^SlJ^7^hSS' {^J^-fS^A-LABEL Sr{R»l7 

i, * i, * 
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[0347] f-^-feiyh^-SK % ^"f±yh^—SK ^Zf±yb^SK <D%jtf:tl\^ 

a, b c, d e, f 

[0348] v^-mmu^(D^{m^\m^X(D^mmm^tc^±yb^-(D^ 

E(SK ,Kc),E(SK ,Kc),E(SK , Kc) 

a, b c, d e, f 

[0349] m32izi®mmmN=i6izmfeLtcmm*Mm^^x, tfiius, uii, ui 

2, 20 3, 13 

[0350] y^-^$^V^jfa^2oOf-yir5/hS tS <D^~T tifrK^ttl. ] M 

2, 20 3. 13 

— ?&tiZ>%:imffltu5, ull, ul2\Z%:<D\,^~ftilz.h<&titi^^(DX\ rto^^-fe 

2, 20 3, 13 

[0351] mmm^m<D^mmm^^^x, mzz\^^7v-%^m^xtw\-rz> 0 m 

?>[Z^7u—^(D&^ : Ty-?\Z-D\^XtW\i-Z)o 
[0352] £-f WflH^Crcm, ^X5/7 0 S60ltc:joV^, ytf-^SfSH, 1-ft;b*>i£{§ 

[0353] 7^^^^7°S602{C^oV^T, ^^L^yjK-^^«l^^"r5Pgl7^<^!;-7 

mZ2<DmX\t, ] M-^imtLX^imu5, ull, u12£j1^LT&^ lit 
31^iryM32o(W:/-feyhS is tft5 0 

2, 20 3,13 

[0354] ^^7°S603^joV^T, ^^L^^^h^^-rs^ir^h^-^il^-T?) 
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[0361] gfs$&umfi*1\ Bff ^^-^MaiCigffi-rS^feS^f-^-feyh^-SK 

i, j 

lz.ttfo1rz>y~7±iyhs tfV-Kjfl^ TIE (A), (B)tf>i^1';h/?&5a^Jj£1-5„ 

i, i 

(A) ^{f »E^7^LABEL £&o/-KkOTBfcT*&5 (fc;£Lj =k<B» 

i, k 

i, k 

i, * 

i, * 

[0363] (B)^#^(C(i,TfSO«t5(^^fB«l^^bttTV^^^l7-</HL 

P(n), S(n) 

i, k 

[0364] *i» , i=P(n), j=k=S(n)-e*>5«^(c« % ^{f «-r^^™^</W = 

P(n). S(n) 

P(n), S(n) 

(H) n^B/"KP (n) ©$felOSy-KP (P (n) ) £#i,&£U y-RP (n) (7^j&y- 
KS (P (n) ) tciiJ-JS-fS^S'JJifcf-^-feyhSS <D tp Iffl^/HL 

P(P(n)).S(P(n)) P(P(n)), S(P(n)) 

[1:65] 
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S(P(y)) P(P(y)), S(P(y)) 



= ( IL p(y),s(y)) +H{y\\salt y ))moAM 



[0369] tfc, ^my^iL . ^tz.n, ^my^^TL IZ#LX, T5£, 

1, 2 1,3 

IL =((IL ) 2 +H(3||salt ))modM 

1, « 1,2 3 

IL =((IL ) 2 +H(2||salt ))modM 

1, * 1, 3 2 

1, * 1, * 

Z.b&X%% 0 

[0370] ^{f^^ioT^tTl-^*^W^^^7-</^#^ai(CoV^, 032Sr#figLT 

9, 18 

4. 8 4, 8 

IL =((IL ) 2 + (19||salt ))modM 

■1.8 9.18 19 

[0371] /-V4(Dmy~V2t5l%/~V5Xtkfe£tlZ>-y-y'-tybS (Dtpffly^ 

2, 5 

;WL 

2, 5 

IL =((IL ) 2 + (9||salt ))modM 

2, 5 4, 8 9 

bl>X&ibZ>z.k&-?%Z> 0 

[0372] C^^a^«9jgLTVKClt^J:«3, ^{f$lu4te. ift^P^^/HL , %>£X$ 

1, 3 

IL ^^465ri^-e^r§ o 

1, 4 



WO 2006/030635 



99 



PCT/JP2005/015814 



7^A-LABEL =Hc(IL ) £:LTff^L, 
SK =G (LABEL ) 

1, <f> M 1, <j> 

i, <* i, * 

[0379] ^{fai-J:oT^Tl-^Ht^^^^^^h^-©^#,m^ao¥M 
[0380] ^v-yy°S70UL^^xm^X^it-r^t, ^T^7 D S702^*DV^T, 

[0381] ^FrXfrlkfeLtcb, ^^3703^^ ^X, SlUf ^OBg^OBt^b^ 
[0382] ^^r^^^-<Z)^m^S(7)Plffl¥Ili^coV^T, El36£#J$LTf&K1-5 0 

i, j i, j 

(A) iSISm^liiLg^-^LABEL £^o/-Kk<Z)?--#-?fc3 (fcfcLj =k^m 

i. k 

(B) y- Ki<7) 7-/- KW^> , gfi*^ ^ Xbfltz)) —7 {%) nfrbtV- h^(D 

i, k 

— h*k(DJ-MX%Z>fr) 
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[0388] ^my^^XUy^^^mmX P£Jl*£MLfcSD(Subset Differ 
ence)tt\Z.m^XWtl£tZ>y-^yY&* ^J^-T^^A- (LABEL) cf % # 

[0389] ^m^^xxf7^j^^mi2iz^xmm.i-^mi^^yh\t, 

i, j 

i, * 

[0390] cfi |57'</l'*5«tU ? 7^^^¥S712W:, SD (Subset Difference) *^»CS<5 
l v rK£1-3f-:/i?S'h#* {zMJtir^y^/^ (LABEL) ^ WJf-^-feyMiifcl-JS 
1"57^<^^*f JS"t"5 4* P^^/V^Rabin TreeO/— K^fitNVtLT 

o 

[0391] MWCtt, -^IrI* (Rabin Tree)£$¥I£7im, 3fetCH8<D7n-*:#flg 
LTlfeP^LfcT^yXA^^oTy-KmfS^lS^LfcRabin Tree££fifcU 

i, 1, * 

[0392] £fbi^ l^^/WcS^^yi^^fflgMcKiJ;^^^^ 

m 22&^mLxmn uztm-?&z> 0 

[0393] Hft7-<Mfc?£¥J£713{3\ l^li*^^/--Km(Z)S:fSm^^«^7-< 
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P(n),S(n) n 

[0400] jyfc#J^}2, ^{tm^TLhtl, ^y725m*&<ft$tbTV^f ffl7^HL 

P(n), SCn) 

n 

[0401] ^i?yh^~£/&#l£723te\ ^^U725tC|§-^$tlTl/^7^, 9 

[0402] ffl■^¥©724tt,^^^y^^-^¥S723i^:feV^T3¥WL^1^^•feyh^-^c: 
[0403] 1*139^ Bf^^^aSrHfir-rstf ^^ffl^m. &£<«-^3dg-^M£ll 

^7^-^803 te, ^fM800^m«^itf ^O^i9W£Uc<9, TlSr1~ii*b 

[0404] tn$R*MSift800l3:, ISd39tC/j;"f ±5^, =*vbn— ^801, ^.^yh802, A 
IhJj^y^y^— 7,803^ -fe^rz.TRrf1t£|S804 % ^^Rd'ts^805, xV*:7°W*£R8 
06, 7<T : VT-r^^^-^807^#x.§ o 

[0405] =^hn— 780113, fM^^Vt 0 ^-^-7V^A^^o^:x--^^a^^tT-rS 
fl!iJWf^LTO^$r^-r^CPUtCioTlS^$tL5 0 ^-^-^802^ $JxJf 
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tttfj^\Z$\\m£tiZ> 0 ?LfjT4^&7x.—X807fe, CD, DVD, MDf©^fV7 

[0411] [12. Rabin Tree«^j2^fflV^SD^(^o^Bf ^Efi^^a] 
SD^^Rabin Tree^j$0||2£iiJBLfcBi ^Iflff , m^SW-O 
V^^^f5o--"^3iffli~SRabin Treete, ©Rabin Tree«J&$j2, 
t>^, [5. Rabin Treelf ^[|2^ML/cCS^(D^] ^fE^L^Rabin Tre 

SRabin TreeTfeSo SD^^Rabin Tree«^2^MfflLfc:Bf -^^ClBff , H 

(12-1) -fey hTyy^S 

(i2-2)Miafi^a 
(12-3) ^m#>£i$m.^%m 

(D&faMtfhZtf, {12- 1) ^yVTyf^m, (12-2)tt$B@fi{f JMiCoV vTte 
, ^Cif @ [11. SD^^Rabin Tree*$fm£MLfcl^;£|Bff , 

[0412] (l2-l)±yhTyy*%±m 

•^yYTyZf^m-t, ±3£<D[5. Rabin Trecfi^2^igfflLfcCS^T^(D^] 
^&^Tf#Pj1LfcRabin Trccf«/jJc£l2£1-5^^te, S^Wi-, Rij3£©[ll 
. SD^^Rabin Trccti^'Jl^iifflL^ WMs^ ^«J(7)J-E 0 (l 1 - 
l)ir^hT^7°^a(c^oV^Ts*P11L/c^^ia(Z)M^fc§ 0 ^KD-feyhTy:/^ ^ 

[0413] Rabin Tree*$0t|2f2, 017iSr#flgLTlft^L^a^-^^^oT 
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E(SK ,Kc),E(SK ,Kc),E(SK , Kc) 

a, b c, d e, f 

X^ 0 

[0420] 5fe^El32^#^LTt^5gLfcj:5i-, ^ff«N = 16^^^Lfc|^ji7K«^^ 
*5V^T, gftt8u5, ull, ul2Sry#— ^i-Sl^^fflV^f-^-fes/Ki, 032^1" 

2, 20 3, 13 

[0421] ] M-^n^^mmi-±2-D(D^±yhS tS <D\ ^-ftlfrKiZttl. Vtf 

2, 20 3, 13 

—^tl^itmu5, ull, ul2l%Z<D\s ^-ffl\^^fl^^(DX\ ^toOf-^i? 

2, 20 3, 13 

[0422] 1t#IE{fMSOM¥)litt,5fe^ll33^t-7n-^#^LTtftPJb^i^^ 

RT^&5„ ^J^^^^LT^ 09fctf, #^2001-35 
2322^fg^^$^TV>^g^^K^ffl1-§^^iiffl^tg-efc§ 0 
[0423] Pf-^bH?IJffli-5f-^-feyh^-tt, flW (TC) J&S-fes'hTs^aH'X 

[0424] y#-^r«Sfi»* s 'fcV^^^tt,M^^20WJ*f-^-feyhSS <£> 

f-y-fe^h^r-SK =G (LABEL )=G (Hc(IL ))fflV^^ttfgOBf 

1, « M 1, <P M 1, * 

[0425] (12-3)g^*3«tt^-^«La 
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/V(» w<»» = (^.w.) ) 2 ® # (»)) mod A/ 



• • • (|fc^6) 

[fte8] 

^L//2j = ( #F / 2 0 ^ ""'(/)) mod M 

[0431] ££>i£, ±ffiy-K©/— WlS^iSNV(4'|^7^)W:, T&^K<ZV~K*tJ£te 
[0432] (al)NV ( = ffRS]7'</WL ) = ((NV ) 2 XOR H salu9 (l9))modM 

9 l, 8 19 

(a2) NV ( = RSJ^/HL ) = ( (NV ) 2 XOR H sal19 (9) ) modM 

•I 2, 5 9 

(a3) NV ( = ^ IBl^/HL ) = ( (NV ) 2 XOR H" 114 (4) ) modM 

2 1,3 4 

(a4)NV ( = ^P^7^ML ) = ( (NV ) 2 XOR H saK2 (2) ) modM 

1 1, * 2 

(bl) LABEL =Hc(IL ) 

9, 18 9, 18 
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[0436] mm^s /-h*4<Dm/-F2tR%;-V5X*fcfe£tlZ>-y-y±yhS (D^m?^ 

2, 5 

ML 3\ 

2, 5 

IL =((IL ) 2 -H salt9 (9))modM 

2, 5 4, 8 

[0437] Z.<Dtm%m*)ML-X^<ZklZ.£*), ^{f Mu4lX t&Wmy^ML , *3,fctf 

1, 3 

IL £3ft«>5££:#-Ct3„ 
i, * 

[0438] ±fE©«t5ICUT,f-^-feyhS ^j^-r^^^^/HL fcagtiJUfc^ 

i, k i, k 

i, k 

LABEL =Hc(IL )bL-X$ilbZ> 0 

i, k i, k 

[0439] ma^, %i\m22&m^xnmut£5\^ mmm^^G^m^x^w^ 

7°±yhS O^A-LABEL ^^^^(^(D^ir^hOf-^iryh^-SK % 

i, j i, i i. j 

SK =G (LABEL ) 

i, j M i, j 

i> j 

[0440] ^im^x^xmri-^^x^m^h^±yh^-om^m^m<DmM 
\*. WR]ir?>%mttmftz>(D%.x\ ftim35(D7u-^-b%0mi>xm.WLtc 

[0441] [13. Rabin Tree«^!l2^iifflL^^:^oV^] 

±3£LfcRabin Tieem}&im%m\^tzSDtt(D^Xmtmj&\^^X^ 
&y-V^jfc\^XmfetS}h%;-mMmmsalt)i)\ gij&ORabin TreeMnm 

Rabin TrcctSMcfmTO, 
[$C70] 



te/? 7 = L//2 j - H (/ || ja// ,)) mod M 

#\ tmp £QR ^lifei-^/J^c7)iE^( 1 bL<^i#^»)^salttLTV^^ 0 ^ 

1 M 1 
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O^D. Halevy and A. Shamir^T'The LSD Broadcast Encryption Sche 
me*j]lllt SD^^^^LfcLayered Subset Difference^^^Hlg^^T 
W5 0 LSD^lCH:, Basic ^©&!gTfc5General(— J&ft) 

tfSfcSo ^r-e«Basic^(CoV^T|^PJ!i-5o 
[0446] LSD^r^ttSD^Oite-CfcO, W^^V^fT^fl!S^^I9A^f^^-efc5 
o SD^^^^S^atO^T'^^i^^Sr^'J^/V (Special Level) iLT 

[0447] flS^fctf), log l/2 N£3g$r<?fc5£1-5o ^-^^LSD^TIi, 041 

[0448] ^-C/^LSD^^V^fi, SD^^^V^Sa^fcf-^iryhS 05t> 

i. i 

, (1)/— Ki^y-Kj^lRl— W-ttcfe^\ fcUttte)/— Ki##giji^/Wcfc5a> 
v^Tfflv^nfc^-tyh^5*>^vKod^4^<— ->^SD;^"Cra:Sli£*ufc< 

i, j 

S = S us 

i, j i, k k, j 

[0449] 0*0, SD^^feV^ttf-^-feyhS ^*J-JSi"5f-^-feyb^— SK £ffi^T 

i, k i, k 

^\tUz.l^(D^X(0\\t>mz.^'- v-y^LSD^^^oV^T^^iryhS 
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-(log 3/2 7V + logiV) 



[0454] mz/-mm%\^^hzh(D$:^7LZ>b, ^m^m^n^i^^m 

[»74] 

s;:f(iog"^)/=i(iog 3/ ^ + iogiv) 



[0455] V^3=, Ki^2KpijlJl/^/^^fe«9, 7-Kj^[w)-Wt^fc?)t(D^£iSLTic^c 
[§C75] 
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i, j i, ♦ 

9, 18 19 1,5 

, LABEL , LABEL , LABEL t, lO©^f B l7^HL <D&ftr5U%Qk 

1, 8 1, 18 4, 18 9, 18 

[0459] mmmm&N thtzM-s^mn ^mm^^^^m^^^o ^ 

i, j 

[0460] y-Ki, j^^M^{3l*oTV^^#lJ:i4, J^T©3o©f^^^i^5„ 

(a) /-mmm^Mzh^o 

(b) /-KjjWBiJi^WiifcSo 

(C) y-Kitjt#SiJl/-</K^V \ 

i, j 

SD^T^Jt£MM£;ft3fc#\ ^fWfi^n^^l-^LEBEL £{&*#LT 

i, j 

[0462] ^MSrfflV^T, rto(7)logNfi(7)7-</^lo(7)#!(JiJ/^-<^, locDTO^ 
logN + l-l=logN 

[0463] ±^<7)J:5^, ^-^^LSD^^1^{M^^1"^9-<^^ic«, 
log 3/2 N + l 

log 3/2 N-logN + l 
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u(DW&<Doh-^\ZhZ>Wt.^ [x] (->) n&&<D%&&U [0] (-») f«n<7)?lj-e 
[x+l](-»)0[0](-»ht>L<H:, [x] H)a'[y] (-») (fcfcXa* 
>aT-fel9, [y] (-») fi[0] H)^IHCfi^Offi^(Dic^lJ)(DV^ tl^^^^^y 

S Sri-^T^-TS. 

i. j 

[0470] r<Z),t5^1"5t, >^LSD;fo£te, -^bLSD^^*o^Td = 2T\ (— 
#£©)l:i^T^0T;fe52ffi<D^T;^ 

fc£*.ffi=825917, j=864563^-f i^j— <DM&. 1" 

i. j 

825917^825920^826000-^830000^864563 
[0471] k =825920, k =826000, k =830000t*5tttf* f"7^hS it 

12 3 i, j 

[*77] 

•<>',. =-V, i U^ < ,U.S' s .,,U.v ii , 

[0472] SBttcDj-mWy'-tybS (CJBi-5§:fI«}c^tf #^^-T5fc*lC|i, 

i. j 

[#78] 
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[0476] [18. Rabin Tree^igfflLfcSD^OHf-^iBff «j£fcfc3tt5fH£*tf>8iJ$c 
[0477] feM(DSDtt(DmfflU]jmz.MU ±^LfcRabin Tree^ffilYfofc^tCJ: 

o 

[0478] RSABf-^^-IJfflL^SD^ir^LSD^^^oVNTSi, gfg$#fc5/-K<£>&NK 

i 

Bfe79] 

NK L//2J 



[#80] 



A« |//2 | = / 0 #(/)) mod M 



[0479] rrT\«^SfP^^^/N^^^^HO^^#^PJ#^i-4^i:b^T#^ 
NK e modM 
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^tz.&&x*h, NK e modM(D&mazm(Dmwtm<D&mwft'&^xm, * 

[0484] ^5feM^SD^5t N S^LSD (Basic LSD) , -$£{bLSD (GeneralLSD 

SDtt: (l/2)log 2 N+(l/2)logN+l{i 
g#LSD#5£ : log 2/3 N +1B 
-jBtftLSD^ : O (log 1+ £ N) 

[0485] rtL^LT, #3693<0Rabin Tree^ilfflL^^ll, gitm^^^^ 

i, j 

i, * i. * 

Rabin Trec^iifflLycy-Km^^^i-^^p^^^^^L, M^y^ 

[0486] ft*3, ^fgW^f/^-fe^Tte, y-WJll^salttt^^lC^i- 

V \ Kf J-*ll^»saltttT-Ji92K'yh^V ^/h^lMXTfeO , (C&ttS 

[0487] ^«t5(-, *38W©«$£»ffl^5rfcfc«fc!K Sfg«i-*5V^^^^-f5^ 

[0488] m^<o%m\m^mx^wb, *&m\^^xmiLx%tz 0 U)*\ji&b. 
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TORabin Tree££$U /— K*fr&ffiNV ^/K£Mo<DT&y— K£*ttS 

a 

b b 

sr^spr^^ij, $i««-^c, gam, m ^ant^^^^^o 
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Kl(^)<7V-K*tJ£{fiNV (1 = 2, 3, 2N-1)^)\TS;, 
Bfcl] 

NV liii] = (NV , 2 + H (/ || salt ,)) mod M 

M 

^y-Km^LT(D^i5::N^,^MW^X: | M | ^AJltU 
^ '2:Z 0^^ai^t-^,-75/fcV^HiSc:H^fe^, 

M 

^X^/7°3 : HufB2^^±fiy-KTfc^-hy-KO/--K^fii:NV £NV 

1 1 

M 

^x^7 D 4:l(^/^)^^^^tT2^^2N-l*Tlf : oJf^n$ii:^^^-ffBa, b 

a. Tr'cI^ 
[Sfc2] 

temp , = (NV L//2j - H (I. \\ salt ,)) mod A/ 
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[8] mm~jjfo*±f&^y7'^ 

1 M 

a. Tf£^ 



temp j = (NV l}/2 ,0 7/ ""'(/)) mod M 



i 

b. imp 1/2 modM£*J?\ 4o<D^(D5^V^X/^£r, KK^VlO CD/— K*j" 

i 

2N-l\n(D | M | fj/K)$c(/— KfcfJ&iE) :NV , NV , NV 

1 2 2N-1 

2N-2flS(Z)ic(y-K#^l^ic) :salt , salt , • • •, salt £tU;frU -to^2 

2 3 2N-1 
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NV lii2]= {NV } 2 0 H w "(/))mod M 

i 

[10] plfi-*^]*4^7^tt 

1 M 

a. TnE^ 

[»6] 



tew/? j = (NV I //2 I © # M " ' (/)) mod M 



i 
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NV lui\ = (NV , 2 + H salt ,)) mod M 

M 

[14] ttimy-v^—w^T-yyix 

NK = Hc(NV) 

fcfc'U NK:7-K^-, NV:/-K*t/Sfii\ Hcr^ytV^liit 

[is] mmy-h^-^m^yyix 

2^^V>T±f4:y— K^)^i|>S05fe (breadth first order) -W-^Lfc./— K# 

^l(^^)cD^^$tLfc^-y-Kl(^/^)0/— K^fgNV (1 = 2, 3, 2N-1) 

i 

[&8] 

^L//2J= (^/ 2 ® // 5a/// (/)) mod M 
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NV li,i]= (NV, 2 ® H sah '(l))mod M 

1 

a 

b b 

[is] tfriE-^iPi^^fife^att, 

£<5<Rabinl£^£aiJBL;fc^&ffl(^ 
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a. TbE^ 
Bfcll] 

temp j = (NV Yf, 2 ] ~ H (/ || salt ,)) mod M 

I 

i 

2N-lf0(D | M | tVh©i£(/-K*j-j£iiS) : NV , N V , ■ • • , NV 

12 2N-1 

2N-2{@<«(y-Ktt#n^$0:salt , salt , salt SrttJ^U Ztlb&2 

2 3 2N-1 

1-^M*^20ic^gE(7)'W«aSrSo 

[22] HfjRd/-K*— ^Hl¥ttt, 

y-K^-NK^, #y-K^(7)y-K^fiSNv^A^iu m$aic%mmvx 

ftW^Sfatft-Cfc^ mjfiE!«HcEi, /-R^ffiNV^y-K^-NKW-fX^ 

[23] HfrSd-^|nj7tC^^-®tt % 

bit"MfS5t (breadth first order) "Ctt-S-Ui:/— K#-^H (^/V) <Dffllfe£tl fc&/— 

n(^)<D/-mitMNV (1 = 2, 3, 2N-1)1)K 

i 
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b. tmp modM^tft, 4^<DM<D5h<D\t^°ftli)^ J— Kl 0x^)0)/— K*f 
1 

2N-1{|@© | M | tVh^icU-K^fjg) :NV , NV , • • NV 

1 2 2N-1 

2N-2B(Dm/-} f ttM^m :salt , salt , • • salt £tH;0U rtl£>£2 

2 3 2N-1 

Kl (1= 1-2N- 1) ©y-K^flS*Dct tJV--Rtt£n«£:-f 5 , 

a 

~K(C^LTt£££;ftfc/~R#^iSNV i/-RM««salt ^m^XIWO 

b b 

WW LfcSD (Subset Difference) ^KS^l ^TR^fSl^irs* 
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temp , = (NV | ll2 | @ H sa " ' (/)) mod M 



Ak M*i£t1-S5p**J*C*5J;9/ift'J^»ES»:salt*Solt5„ 

l 

b. tmp 1/2 modM£fJ&#), 4o£);fi?(£>5^C9V ^-f fbfr%^ KK^/l')?)/— K#t 
i 

i 

2N-lM<D | M | tVh^(y-K^jjt) :NV , NV , NV K 

1 2 2N-1 

2N-2{i(7)m(7-K#iP^ic) :salt , salt , • • salt SrtfJ^U 

2 3 2N-1 

#*<£>#/-Kl (1= 1-2N- 1) ©y-K^MfcctT^y- 

±ie^^°(cioT-^^^^««^fc§ri^#mi-r5f**ii25^ 
HuEBt ^ca^, s E,(D^1-^/-K^^^SNv<^/-K'^^p^salt^sov^ 

Bf5-j!C^jgffly-K=3r-$r, Q B<D^-r^y-K*f^{i£NV^/--K#^l^iCsal 

[28] Mftm^xm&^mK. 

^m^(DMc±iiLj—VbLX(D;P-h$:lbUt?&U9c (breadth first order) t? 
^1-^O^^ott^^Tfe^^#mti-^lt^il27^|Bic(Dtf^^a^fi 



WO 2006/030635 



143 



PCT/JP2005/015814 



mm 

NV lJii] = (^V , 2 © H "*'(/)) mod M 

i 

[32] ^g7fcS^c^^<^n-K= 3 r^h^^y^>3>'^-^fe^SD (Subset Diff 

\.b\z&^<mR&m*'Mft\.xmwzf±vYtt),^ 
^^y'±yb^-mmvx^X(Dm^M^mnirm^^t^u 

2ftM^ "X ±{fc/- KA^M5fe (breadth first order) "Cfa^Lfcy—K* 

^-l (^) <7)is:^$tbfe#y— KK^/v)©/— K^fJSflSNV (1=2, 3, 2N-1) 

1 
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